Vulnerabilities/

Storybook Dev Server is Vulnerable to WebSocket Hijacking

Severity:
High

Description

The WebSocket functionality in Storybook’s dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted.

Recommendation

Update the storybook package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
storybook
Anything's wrong? Let us know Last updated on February 26, 2026